Hot Take Malicious website escaping secure dns

Yeah, looks like it. This is how Cloudflare categorize the site,
View attachment 293463
So, I went to submit it to Symantec who were not detecting it. I choose category "Compromised Sites" and after like 5 seconds got a reply,
View attachment 293464
I checked it when first posted against all url checkers, including VT, Norton safeweb, K TIP, B url check, and others; all came clean.
That's why I suspected it was hijacked, especially after @rashmi reported change of page of the exact web address.
 
Now the website loaded and it showed the fake Chrome update page. But I got a warning before visiting that the site does not support secure connection, but when I accepted the risk, it loaded without any interactions from BD.

Btw clicking on Update Chrome does not do anything.

IMG_20251204_181012031.jpg
 
Take home message: Do not "entirely" rely on any security layer; response may take some time.
Common sense (prompt on browser other than Chrome, prompt on up-to-date Chrome, "CONTINUE" in capital letters, lack of logic that website cannot load except on the latest update of a browser) is your first line of defence.
 
The update button leads to download a malware that's based on Node.js (the most popular JavaScript runtime environment).
ESET didn't block the malware download source site like Kaspersky, but the main malicious file was detected after extraction.
View attachment 293470
How did you manage to download the infected file? I thought the server that's hosting the malicious files was taken down.